First published: Sun Nov 10 2024(Updated: )
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Simple Music Cloud Community System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11054 is classified as a critical vulnerability.
CVE-2024-11054 affects the /music/ajax.php?action=signup file, allowing for unrestricted file uploads.
The vulnerability can be exploited by manipulating the pp argument in the signup action.
Yes, the unrestricted file upload could potentially allow for remote code execution.
To mitigate CVE-2024-11054, ensure you apply the latest security patches and validate file uploads properly.